Validate
Static validity is necessary; useful local behavior is the release gate.
recipes check ./my-recipe
recipes setup
pi --recipe ./my-recipe --agent agentrecipes check validates package structure, agent inheritance, declared resources, capability policy, judges, and pinned eval references. recipes setup ensures the companion Pi extension exists before a direct path launch; installing a recipe performs that setup automatically. Then exercise representative work in Pi and inspect the actual tool and instruction boundary.
Hosts can embed the same validator and resolver. They should not invent a second interpretation of the recipe.